Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-90461

Опубликовано: 11 сент. 2026
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

A flaw was found in OpenStack Ironic. When the Image Service is configured for HTTP(S) Basic Authentication, Ironic may inadvertently transmit a username and password to an unintended remote host. This could lead to the disclosure of sensitive authentication credentials to an attacker who controls the unexpected host.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2532451ironic: OpenStack Ironic: Information disclosure via unexpected credential transmission

EPSS

Процентиль: 11%
0.00207
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
1 день назад

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

CVSS3: 6.3
nvd
3 дня назад

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

CVSS3: 6.3
debian
3 дня назад

OpenStack Ironic through 38.0.0 may send a username and password to an ...

CVSS3: 6.3
github
3 дня назад

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

EPSS

Процентиль: 11%
0.00207
Низкий

6.3 Medium

CVSS3